О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.10.0).
- Security fixes:
+ CVE-2021-23994 Out of bound write due to lazy initialization
+ CVE-2021-23995 Use-after-free in Responsive Design Mode
+ CVE-2021-23998 Secure Lock icon could have been spoofed
+ CVE-2021-23961 More internal network hosts could have been probed by a malicious webpage
+ CVE-2021-23999 Blob URLs may have been granted additional privileges
+ CVE-2021-24002 Arbitrary FTP command execution on FTP servers using an encoded URL
+ CVE-2021-29945 Incorrect size computation in WebAssembly JIT could lead to null-reads
+ CVE-2021-29946 Port blocking could be bypassed
О пакете: Library providing a simple API virtualization
Изменения:
- backport fixes from 6.7.0 and 6.8.0 (Fixes: CVE-2020-25637)
О пакете: Xserver - X Window System display server
Изменения:
- fixes: CVE-2021-3472
О пакете: Clam Antivirus scanner
Изменения:
- 0.103.2
+ CVE-2021-1252, CVE-2021-1405 - 0.103.0 and 0.103.1 only.
+ CVE-2021-1404 - 0.103.1 and prior
О пакете: A lightweight caching nameserver
Изменения:
- Dropped obsoleted patch.
- Updated to 2.83 (fixes: CVE-2021-3448).
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.28 (Fixes: CVE-2021-29657)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.28 (Fixes: CVE-2021-29657)
О пакете: Gets a file from a FTP, GOPHER or HTTP server
Изменения:
- 7.76.0
- Fixes:
* CVE-2021-22876 strip credentials from the auto-referer header field
* CVE-2021-22890 add 'isproxy' argument to Curl_ssl_get/addsessionid()
О пакете: IT and asset management software
Изменения:
- New version 9.5.4
- This is a security release, upgrading is recommended
- Security fixes:
+ CVE-2021-21326 : Horizontal Privilege Escalation
+ CVE-2021-21255 : entities switch IDOR
+ CVE-2021-21258 : XSS injection in ajax/kanban
+ CVE-2021-21314 : XSS injection on ticket update
+ CVE-2021-21312 : Stored XSS on documents
+ CVE-2021-21313 : XSS on tabs
+ CVE-2021-21325 : Stored XSS in budget type
+ CVE-2021-21327 : Unsafe Reflection in getItemForItemtype()
+ CVE-2021-21324 : Insecure Direct Object Reference (IDOR) on "Solutions"
О пакете: Spam filter for email written in perl
Изменения:
- 3.4.5 (fixes: CVE-2020-1946)
- remove dkim patch (fixed by upstream).
О пакете: OpenSSL - Secure Sockets Layer and cryptography shared libraries and tools
Изменения:
- Updated to 1.1.1k (fixes CVE-2021-3450, CVE-2021-3449).
О пакете: The Samba4 CIFS and AD client and server suite
Изменения:
- Update to latest security release of the Samba 4.12
- Security fixes:
+ CVE-2020-27840: Heap corruption via crafted DN strings
+ CVE-2021-20277: Out of bounds read in AD DC LDAP server
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.25 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.4.107 (Fixes: CVE-2019-2308)
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.9.0).
- Security fixes:
+ CVE-2021-23981 Texture upload into an unbound backing buffer resulted in an out-of-bound read
+ CVE-2021-23982 Internal network hosts could have been probed by a malicious webpage
+ CVE-2021-23984 Malicious extensions could have spoofed popup information
+ CVE-2021-23987 Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9
- Do not build for ppc64le.
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.25 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.4.107 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.25 (Fixes: CVE-2019-2308)
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.9.0).
- Security fixes:
+ CVE-2021-23981 Texture upload into an unbound backing buffer resulted in an out-of-bound read
+ CVE-2021-23982 Internal network hosts could have been probed by a malicious webpage
+ CVE-2021-23984 Malicious extensions could have spoofed popup information
+ CVE-2021-23987 Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9
- Do not build for ppc64le.
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.4.107 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.25 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.4.107 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.4.107 (Fixes: CVE-2019-2308)
О пакете: The Linux kernel (the core of the Linux operating system)
Изменения:
- v5.10.25 (Fixes: CVE-2019-2308)
О пакете: A TLS protocol implementation
Изменения:
- Fixed gnulib tests.
- Fixed CVE-2021-20231, CVE-2021-20232
(fixes: CVE-2021-20231, CVE-2021-20232).
- Fixed testpkcs11.
- Dropped self-provide from devel subpackage.
О пакете: PyYAML, a YAML parser and emitter for Python
Изменения:
- Backport version 5.4.x to p9 branch (fixes CVE-2020-1747).
О пакете: The BugTraq Award Winning Network Traffic Analyzer
Изменения:
- 3.4.4 (Fixes: CVE-2021-22191)
О пакете: An open source web browser developed by Google
Изменения:
- New version (89.0.4389.90).
- Security fixes:
- CVE-2021-21191: Use after free in WebRTC.
- CVE-2021-21192: Heap buffer overflow in tab groups.
- CVE-2021-21193: Use after free in Blink.
О пакете: OpenSSL - Secure Sockets Layer and cryptography shared libraries and tools
Изменения:
- Updated to 1.1.1j (fixes CVE-2021-23840 CVE-2021-23841).
О пакете: Common Unix Printing System - server package
Изменения:
- Updated to upstream version 2.3.3op2 (Fixes: CVE-2020-10001).
- Project moved to OpenPrinting.
- Fixed license.
О пакете: OpenSSL - Secure Sockets Layer and cryptography shared libraries and tools
Изменения:
- Updated to 1.1.1j (fixes CVE-2021-23840, CVE-2021-23841).
О пакете: The Go Programming Language
Изменения:
- New version (1.15.9).
- Fixes:
+ CVE-2021-27918
+ CVE-2021-27919
О пакете: The Go Programming Language
Изменения:
- New version (1.15.9).
- Fixes:
+ CVE-2021-27918
+ CVE-2021-27919
О пакете: An open source web browser developed by Google
Изменения:
- New version (89.0.4389.82).
- Security fixes:
- CVE-2020-27844: Heap buffer overflow in OpenJPEG.
- CVE-2021-21159: Heap buffer overflow in TabStrip.
- CVE-2021-21160: Heap buffer overflow in WebAudio.
- CVE-2021-21161: Heap buffer overflow in TabStrip.
- CVE-2021-21162: Use after free in WebRTC.
- CVE-2021-21163: Insufficient data validation in Reader Mode.
- CVE-2021-21164: Insufficient data validation in Chrome for iOS.
- CVE-2021-21165: Object lifecycle issue in audio.
- CVE-2021-21166: Object lifecycle issue in audio.
- CVE-2021-21167: Use after free in bookmarks.
- CVE-2021-21168: Insufficient policy enforcement in appcache.
- CVE-2021-21169: Out of bounds memory access in V8.
- CVE-2021-21170: Incorrect security UI in Loader.
- CVE-2021-21171: Incorrect security UI in TabStrip and Navigation.
- CVE-2021-21172: Insufficient policy enforcement in File System API.
- CVE-2021-21173: Side-channel information leakage in Network Internals.
- CVE-2021-21174: Inappropriate implementation in Referrer.
- CVE-2021-21175: Inappropriate implementation in Site isolation.
- CVE-2021-21176: Inappropriate implementation in full screen mode.
- CVE-2021-21177: Insufficient policy enforcement in Autofill.
- CVE-2021-21178: Inappropriate implementation in Compositing.
- CVE-2021-21179: Use after free in Network Internals.
- CVE-2021-21180: Use after free in tab search.
- CVE-2021-21181: Side-channel information leakage in autofill.
- CVE-2021-21182: Insufficient policy enforcement in navigations.
- CVE-2021-21183: Inappropriate implementation in performance APIs.
- CVE-2021-21184: Inappropriate implementation in performance APIs.
- CVE-2021-21185: Insufficient policy enforcement in extensions.
- CVE-2021-21186: Insufficient policy enforcement in QR scanning.
- CVE-2021-21187: Insufficient data validation in URL formatting.
- CVE-2021-21188: Use after free in Blink.
- CVE-2021-21189: Insufficient policy enforcement in payments.
- CVE-2021-21190: Uninitialized Use in PDFium.
О пакете: An open source web browser developed by Google
Изменения:
- New version (89.0.4389.82).
- Security fixes:
- CVE-2020-27844: Heap buffer overflow in OpenJPEG.
- CVE-2021-21159: Heap buffer overflow in TabStrip.
- CVE-2021-21160: Heap buffer overflow in WebAudio.
- CVE-2021-21161: Heap buffer overflow in TabStrip.
- CVE-2021-21162: Use after free in WebRTC.
- CVE-2021-21163: Insufficient data validation in Reader Mode.
- CVE-2021-21164: Insufficient data validation in Chrome for iOS.
- CVE-2021-21165: Object lifecycle issue in audio.
- CVE-2021-21166: Object lifecycle issue in audio.
- CVE-2021-21167: Use after free in bookmarks.
- CVE-2021-21168: Insufficient policy enforcement in appcache.
- CVE-2021-21169: Out of bounds memory access in V8.
- CVE-2021-21170: Incorrect security UI in Loader.
- CVE-2021-21171: Incorrect security UI in TabStrip and Navigation.
- CVE-2021-21172: Insufficient policy enforcement in File System API.
- CVE-2021-21173: Side-channel information leakage in Network Internals.
- CVE-2021-21174: Inappropriate implementation in Referrer.
- CVE-2021-21175: Inappropriate implementation in Site isolation.
- CVE-2021-21176: Inappropriate implementation in full screen mode.
- CVE-2021-21177: Insufficient policy enforcement in Autofill.
- CVE-2021-21178: Inappropriate implementation in Compositing.
- CVE-2021-21179: Use after free in Network Internals.
- CVE-2021-21180: Use after free in tab search.
- CVE-2021-21181: Side-channel information leakage in autofill.
- CVE-2021-21182: Insufficient policy enforcement in navigations.
- CVE-2021-21183: Inappropriate implementation in performance APIs.
- CVE-2021-21184: Inappropriate implementation in performance APIs.
- CVE-2021-21185: Insufficient policy enforcement in extensions.
- CVE-2021-21186: Insufficient policy enforcement in QR scanning.
- CVE-2021-21187: Insufficient data validation in URL formatting.
- CVE-2021-21188: Use after free in Blink.
- CVE-2021-21189: Insufficient policy enforcement in payments.
- CVE-2021-21190: Uninitialized Use in PDFium.
О пакете: Shared library for the Qt4 GUI toolkit
Изменения:
- Applied security fixes (fixes: CVE-2020-17507) (thanks zerg@alt)
- Fixed build with gcc-10+.
- Disabled -reduce-relocation option since it causes issues with new binutils.
О пакете: wpa_supplicant is an implementation of the WPA Supplicant component
Изменения:
- P2P: Fix a corner case in peer addition based on PD Request
(Fixes: CVE-2021-27803)
О пакете: Thunderbird is Mozilla's e-mail client
Изменения:
- New version (78.8.0).
- Security fixes:
+ CVE-2021-23969 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23968 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23973 MediaError message property could have leaked information about cross-origin resources
+ CVE-2021-23978 Memory safety bugs fixed in Thunderbird 78.8
О пакете: A high-level Python 3 Web framework that encourages rapid development and clean, pragmatic design.
Изменения:
- 2.2.19
- rename package to python3-module-django back
- Fixes for the following security vulnerabilities:
+ CVE-2021-3281 Potential directory-traversal via archive.extract()
+ CVE-2021-23336 Web cache poisoning via django.utils.http.limited_parse_qsl()
О пакете: The BugTraq Award Winning Network Traffic Analyzer
Изменения:
- 3.4.3 (Fixes: CVE-2021-22173, CVE-2021-22174)
О пакете: A standard terminal emulator for the X Window System
Изменения:
- Autobuild version bump to 366
- CVE-2021-27135 (Closes: #39725)
О пакете: The BugTraq Award Winning Network Traffic Analyzer
Изменения:
- 3.4.3 (Fixes: CVE-2021-22173, CVE-2021-22174)
О пакете: Evented I/O for V8 Javascript
Изменения:
- new version 14.16.0 (with rpmrb script)
- CVE-2021-22883: HTTP2 'unknownProtocol' cause Denial of Service by resource exhaustion
- CVE-2021-22884: DNS rebinding in --inspect
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.8.0).
- Security fixes:
+ CVE-2021-23969 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23968 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23973 MediaError message property could have leaked information about cross-origin resources
+ CVE-2021-23978 Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.8.0).
- Security fixes:
+ CVE-2021-23969 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23968 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23973 MediaError message property could have leaked information about cross-origin resources
+ CVE-2021-23978 Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Изменения:
- New version (78.8.0).
- Security fixes:
+ CVE-2021-23969 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23968 Content Security Policy violation report could have contained the destination of a redirect
+ CVE-2021-23973 MediaError message property could have leaked information about cross-origin resources
+ CVE-2021-23978 Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8
О пакете: ISC BIND - DNS server
Изменения:
- 9.11.25 -> 9.11.28 (fixes: CVE-2020-8625).
О пакете: .NET Core SDK binaries
Изменения:
- .NET 5.0.3 and .NET SDK 5.0.103
- CVE-2021-1721: .NET Core Denial of Service Vulnerability
- CVE-2021-24112: .NET 5 and .NET Core Remote Code Execution Vulnerability
О пакете: .NET Core foundational libraries, called CoreFX
Изменения:
- .NET Core 3.1.12
- CVE-2021-1721: .NET Core Denial of Service Vulnerability
- CVE-2021-24112: .NET 5 and .NET Core Remote Code Execution Vulnerability
О пакете: SDK for the .NET
Изменения:
- .NET SDK 5.0.103
- CVE-2021-1721: .NET Core Denial of Service Vulnerability
- CVE-2021-24112: .NET 5 and .NET Core Remote Code Execution Vulnerability
1 2 3 4 5 … Следующая › Последняя »